CVE-2026-19483
Analyzed Analyzed - Analysis Complete

IBM Storage Scale Secrets Disclosure in GUI Logs

Vulnerability report for CVE-2026-19483, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-13

Last updated on: 2026-08-18

Assigner: IBM Corporation

Description

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 Secrets may be disclosed in log files in IBM Storage Scale Management GUI The admin password is logged into the GUI log of IBM Storage Scale Systems Deploy and Upgrade from GUI. Secrets may be disclosed in information related to exceptions in IBM Storage Scale Management GUI.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-13
Last Modified
2026-08-18
Generated
2026-09-03
AI Q&A
2026-08-14
EPSS Evaluated
2026-09-02
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
ibm storage_scale From 5.2.3.0 (inc) to 5.2.3.9 (exc)
ibm storage_scale From 6.0.0.0 (inc) to 6.0.1.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

IBM Storage Scale versions 5.2.3.0 through 5.2.3.8 and 6.0.0.0 through 6.0.1.0 have a vulnerability where admin passwords are logged in plaintext within the GUI log files. This occurs during system deployments and upgrades via the IBM Storage Scale Management GUI.

Detection Guidance

To detect this vulnerability, check IBM Storage Scale Management GUI logs for admin password exposure. Review logs in IBM Storage Scale Systems Deploy and Upgrade GUI for any exceptions or errors that may contain secrets. No specific commands are provided in the context.

Impact Analysis

An attacker with access to log files could extract admin credentials, leading to unauthorized system access. This could allow attackers to perform administrative actions, modify configurations, or access sensitive data stored on the system.

Compliance Impact

This vulnerability may violate compliance requirements that mandate protection of credentials and sensitive data. GDPR could be impacted due to unauthorized access risks, while HIPAA may be affected if protected health information is exposed through compromised admin access.

Mitigation Strategies

Review IBM Storage Scale Management GUI logs for exposed admin passwords. Upgrade IBM Storage Scale to versions beyond 5.2.3.8 or 6.0.1.0 to address the logging issue. Restrict access to GUI logs and ensure sensitive data is not logged in plaintext.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19483. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart